First 30 minutes: preserve before changing
- Write a simple timeline
Record when the issue was first noticed, who saw it, what systems were affected and what actions have already been taken. - Capture visible evidence
Take screenshots or photos of ransom notes, suspicious messages, login alerts, bank details, error screens and URLs. - Keep originals
Do not delete phishing emails, scam chats, invoices, attachments, browser history or log files until copies are preserved. - Use trusted channels
Contact banks, platforms and providers through official websites or phone numbers, not links inside suspicious messages.
Evidence checklist
- Original emails and headers
- SMS/chat records
- Web links and screenshots
- Login and account activity
- Mailbox rules and forwarding
- Payment records and invoices
- Device names and serial numbers
- Cloud sharing records
- Security alerts and logs
- People affected and dates
What not to do too quickly
Avoid factory resets, reinstalling systems, deleting accounts, clearing browser history, wiping phones, paying ransom demands or contacting suspected attackers without advice. These actions can make recovery, reporting or evidence review harder.
Send an evidence-aware enquiry
Related help
Evidence checklist
A practical list of what to preserve before logs, screenshots or account records disappear.
Request specialist consultation
Send the facts you have and we will help organise the next steps.
Australian cyber resources
Helpful public resources for cyber, privacy, scams and online safety.